
174 Cyber seCurity essentiAls
e vulnerable search engine queries for the malicious string and
then returns it to the user along with the results. Rather than display-
ing the query text to the user, the browser generates an alert box con-
taining the text “XSS!” demonstrating that code passed by the URL
was executed (see Exhibit 3-31).
At first glance, this vulnerability does not appear to be very dan-
gerous, as the user entered the text that caused the code to execute;
however, attackers often craft malicious links containing the mali-
cious script code, distribute these malicious links via e-mail, or post
them to message boards and simply wa